More specifically:
Who is behind Encryptor RaaS?
The TOR- and Bitcoin-based operation of Encryptor RaaS makes it hard to track the author behind this ransomware. On top of that, the author uses the dark web mail service SIGAINT to talk to clients.
We found that a thread was created in the forum regarding our previous Encryptor RaaS post. A user with the handle jeiphoos has replied to the thread and identified himself as the author of Encryptor RaaS. One of his replies to the thread suggests that he has been or is around many German-speaking people:
Figure 7. Forum post of jeiphoos on
Additionally, his forum profile shows that his local timezone is Central European Time, which is Germany's timezone. Therefore, it is possible that the author is located in Germany or in one of the countries under the CET timezone.